Threat reportVulnerabilityTL-2026-0241

Wing FTP Server RCE Exploit Chain — Lua Code Injection via NULL Byte (CVE-2025-47812 CVSS 10.0 + CVE-2025-47813)

criticalMONITORING

Wing FTP Server RCE Exploit Chain (TL-2026-0241), also tracked as Wing FTP NULL Byte RCE, is a critical-severity software vulnerability scored CVSS 10, first published 2026-03-17. It has no confirmed attribution, affects wftpserver Wing FTP Server, references 2 CVEs (CVE-2025-47812, CVE-2025-47813), maps to 15 MITRE ATT&CK techniques (T1027, T1059, T1068), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
10/10Critical
CVEs
2Referenced vulnerabilities
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0241

Threat ID
TL-2026-0241
Also known as
Wing FTP NULL Byte RCE, Wing FTP Lua Injection
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, technology, manufacturing, education, critical-infrastructure, small-business
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in Wing FTP Server RCE Exploit Chain

Malware and tooling: CVE-2025-47812 Python PoC exploit (4m3rr0r / EDB-52347), ScreenConnect

How Wing FTP Server RCE Exploit Chain works

Critical exploit chain in Wing FTP Server before 7.4.4 achieves unauthenticated remote code execution as SYSTEM/root. CVE-2025-47813 (CVSS 4.3) discloses the full server installation path via crafted UID cookies, while CVE-2025-47812 (CVSS 10.0) exploits NULL byte mishandling in the username parameter to inject arbitrary Lua code into session files, which execute with service-level privileges. Public PoC available since June 2025; active exploitation confirmed by Huntress since July 1, 2025. CISA KEV additions: CVE-2025-47812 on July 14, 2025; CVE-2025-47813 on March 16, 2026.

Wing FTP Server versions prior to 7.4.4 contain a critical exploit chain combining two vulnerabilities that together achieve unauthenticated remote code execution with SYSTEM (Windows) or root (Linux/macOS) privileges.

## CVE-2025-47812 — Lua Code Injection via NULL Byte (CVSS 10.0)

The core RCE vulnerability stems from improper handling of NULL bytes (\0) in both the user and admin web interfaces. The exploit chain operates through four interconnected weaknesses:

1. **NULL Byte Truncation in Authentication**: The c_CheckUser() function uses strlen() on the provided username. When a NULL byte (%00) is injected into the username, strlen() truncates the string at that point, causing authentication to succeed for the portion before the NULL byte. This allows exploitation via anonymous FTP accounts or any known credentials.

2. **Unsanitized Session Creation**: Despite authentication validating only the truncated portion, the rawset(_SESSION, 'username', username) call in loginok.html preserves the entire unsanitized username from request parameters, including the NULL byte and all subsequent characters.

3. **Lua Script Session Storage**: Wing FTP Server stores session data as executable Lua scripts on disk. The injected payload — crafted as valid Lua code after the NULL byte — is written directly into the session file.

4. **Session File Execution**: When an authenticated endpoint (specifically /dir.html) is accessed with the session UID cookie, the SessionModule.load() function executes session files via loadfile(filepath) followed by f(), triggering the injected Lua payload with full service-level privileges.

A typical exploit payload follows this structure: `anonymous%00]]%0dlocal+h+%3d+io.popen("command")%0dlocal+r+%3d+h%3aread("*a")%0dh%3aclose()%0dprint(r)%0d--` where `]]` closes the existing Lua table syntax, `io.popen()` executes arbitrary system commands, and `--` comments out remaining session data.

The attack requires only two HTTP requests: (1) a POST to /loginok.html with the crafted payload in the username parameter, and (2) a GET to /dir.html with the returned UID cookie to trigger execution.

## CVE-2025-47813 — Installation Path Disclosure (CVSS 4.3)

The loginok.html endpoint in Wing FTP Server before 7.4.4 discloses the full local installation path when an excessively long string is submitted in the UID cookie. This information disclosure (CWE-209) reveals sensitive server configuration details that aid exploitation of CVE-2025-47812 by exposing the exact filesystem location of session files.

## Active Exploitation

Huntress observed the first in-the-wild exploitation on July 1, 2025 — one day after Julien Ahrens (RCE Security) published the detailed vulnerability write-up and PoC on June 30, 2025. The patch (v7.4.4) had been available since May 14, 2025, but many installations remained unpatched.

Multiple distinct threat actors were observed exploiting the same victim from different IP addresses. Post-exploitation activity included network reconnaissance, creation of new local user accounts for persistence, attempted download and execution of malicious batch files, and deployment of ScreenConnect (ConnectWise Control) remote monitoring and management software. Microsoft Defender blocked several malicious activities on the compromised host.

Censys identified approximately 8,103 exposed Wing FTP Server instances as of July 9, 2025, with roughly 5,004 having exposed web interfaces potentially vulnerable to exploitation. Only 105 devices publicly reported version numbers.

## Related Vulnerabilities

CVE-2025-47811 is an additional privilege escalation vulnerability in Wing FTP Server that remains UNFIXED even in v7.4.4. CVE-2025-27889, an information disclosure flaw revealing cleartext passwords, was fixed in v7.4.3 (released March 26, 2025).

## Impact

Successful exploitation grants full SYSTEM/root-level command execution on the underlying server, enabling complete compromise of the host including data exfiltration, lateral movement, ransomware deployment, and persistent backdoor installation. The vulnerability is particularly dangerous because Wing FTP Server typically runs with maximum privileges by default and is commonly deployed as an internet-facing file transfer solution.

MITRE ATT&CK techniques used in TL-2026-0241

defense-evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1078 Valid Accounts

execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071 Application Layer Protocol; T1219 Remote Access Tools

discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

persistence

T1136 Create Account; T1505 Server Software Component

initial-access

T1190 Exploit Public-Facing Application

impact

T1485 Data Destruction

Affected products and versions in Wing FTP Server RCE Exploit Chain

  • wftpserver — Wing FTP Server
    Vulnerable versions: 7.4.3 and earlier; All versions before 7.4.4
    Fixed in: 7.4.4

Remediation for Wing FTP Server RCE Exploit Chain

Patches

  • Wing FTP Server v7.4.4 — fixes CVE-2025-47812 and CVE-2025-47813 (released May 14, 2025)
  • Wing FTP Server v7.4.3 — fixes CVE-2025-27889 cleartext password disclosure (released March 26, 2025)
  • Note: CVE-2025-47811 privilege escalation remains UNFIXED in v7.4.4

Immediate actions

  • Update Wing FTP Server to version 7.4.4 or later immediately
  • If patching is not immediately possible, disable anonymous FTP access
  • Restrict access to Wing FTP web admin and user interfaces (/loginok.html, /dir.html) to trusted IP ranges only
  • Monitor Wing FTP Server logs for POST requests to /loginok.html containing NULL byte sequences (%00) in the username parameter
  • Audit local user accounts on Wing FTP Server hosts for unauthorized additions
  • Block known ScreenConnect/ConnectWise Control domains at the firewall if not authorized

Workarounds

  • Disable anonymous FTP access on all Wing FTP Server instances
  • Place Wing FTP web interfaces behind VPN or restrict to internal networks only
  • Implement IP allowlisting for web admin and user interface access
  • Enable verbose logging and monitor for suspicious POST payloads to /loginok.html
  • Deploy host-based intrusion prevention (HIPS) to block Lua script injection into session files

Longer-term hardening

  • Deploy EDR/XDR with behavioral detection for anomalous child process spawning from wingftp.exe or wftpd processes
  • Implement network segmentation to isolate file transfer servers from critical infrastructure
  • Establish a vulnerability management program with SLA-based patching for internet-facing services
  • Deploy WAF rules to detect and block NULL byte injection attempts in POST parameters
  • Consider migrating to a file transfer solution with a stronger security track record
  • Implement application allowlisting on Wing FTP Server hosts to prevent unauthorized binary execution

CVEs associated with Wing FTP Server RCE Exploit Chain

CVE-2025-47812, CVE-2025-47813

Weaknesses (CWE) in Wing FTP Server RCE Exploit Chain

CWE-158, CWE-94, CWE-209

Timeline of Wing FTP Server RCE Exploit Chain

  • Wing FTP Server v7.4.3 released, fixing CVE-2025-27889 (cleartext password disclosure) but not CVE-2025-47812 or CVE-2025-47813
  • Wing FTP Server v7.4.4 released, fixing CVE-2025-47812 (Lua injection RCE) and CVE-2025-47813 (path disclosure). CVE-2025-47811 privilege escalation remains unfixed
  • Julien Ahrens (RCE Security / @MrTuxracer) publishes detailed vulnerability write-up and proof-of-concept exploits for CVE-2025-47812, CVE-2025-47813, and CVE-2025-47811
  • Huntress observes first in-the-wild exploitation of CVE-2025-47812 on a customer environment — one day after PoC publication. Multiple threat actors observed performing recon, creating accounts, deploying ScreenConnect
  • Huntress publishes detailed exploitation analysis documenting post-exploitation activities including reconnaissance, local account creation, batch file download attempts, and ScreenConnect deployment
  • Censys identifies approximately 8,103 exposed Wing FTP Server instances globally, with 5,004 having exposed web interfaces vulnerable to the exploit chain
  • NVD publishes CVE-2025-47812 (CVSS 10.0) and CVE-2025-47813 (CVSS 4.3). Public PoC exploit (EDB-52347) listed on Exploit-DB
  • CISA adds CVE-2025-47812 to the Known Exploited Vulnerabilities (KEV) catalog with remediation due date of August 4, 2025 under BOD 22-01
  • CISA adds CVE-2025-47813 to the KEV catalog, recognizing the full exploit chain. Remediation due date March 30, 2026. Renewed exploitation activity against unpatched Wing FTP instances confirmed
  • As of 2026-05-29, this Wing FTP RCE chain is patched in v7.4.4 but remains an active threat to unpatched, internet-exposed servers (8,000+ originally exposed, anonymous-FTP exploitable). CVE-2025-47812 has been in CISA KEV since Jul 2025 and CVE-2025-47813 was added Mar 16 2026 with continued exploitation reported, so it stays under MONITORING.

Sources cited for Wing FTP Server RCE Exploit Chain

Detection coverage for TL-2026-0241

As of 2026-03-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0241 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats